Back to skill

Security audit

Session Password

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed session-password guard, but its authentication, recovery, and billing implementation has serious security and consent concerns.

Review carefully before installing. This skill handles session access, recovery secrets, local audit/state files, and paid billing calls, but the reviewed artifact has major implementation gaps and unsafe secret-handling patterns. Do not rely on it as a security boundary unless the authentication schema, recovery flow, billing consent, and hardcoded credential issues are fixed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (7)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/billing.js:12
Finding

Hard-Coded Production Billing API Credential

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/setup.js:22
Finding

Authentication Guard Is Not Reliably Enforced Due to Incompatible Configuration Schemas

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/email-recovery.js:23
Finding

Recovery Codes Use Non-Cryptographic Randomness and Have No Attempt Limit

Content
View full analysis
record.expiresAt) { return { valid: false, error: 'code_expired' }; } const inputHash = hashRecoveryCode(inputCode); if (inputHash !== record.codeHash) { return { valid: false, error: 'invalid_code' }; } record.used = true; fs.writeFileSync(RECOVERY_FILE, JSON.stringify(record, null, 2)); return { valid: true }; } ``` ### Technical Analysis `Math.random()` is not a cryptographically secure random number generator. Recovery codes are limited to 900,000 possible values, and verification does not record failures, impose an attempt limit, rate-limit calls, or introduce a lockout. An attacker able to call the local verification function repeatedly can enumerate the entire token space during the 15-minute validity period. The token comparison is also not constant-time, although brute-force exposure is the dominant concern. The complete password-reset fu ...[truncated 1202 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/email-recovery.js:85
Finding

Plaintext Recovery Code and Email Are Exposed in Stub Mode

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/email-recovery.js:174
Finding

Password Recovery Downgrades Credentials to Unsalted SHA-256

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/auth-core.js:307
Finding

Authentication CLI Exposes Passwords Through Process Arguments

Content
View full analysis
Commands: status - Check authentication status verify - Verify passphrase refresh - Refresh lastActiveAt clear - Clear authentication state ``` ### Technical Analysis The CLI accepts the plaintext passphrase through `process.argv`. Command-line arguments may be exposed through process listings, shell history, terminal telemetry, wrappers, crash diagnostics, audit frameworks, or orchestration metadata. Hashing the password after receipt does not mitigate disclosure that occurs before verification. ### Attack Path 1. A user invokes `node auth-core.js verify ` as documented. 2. The plaintext password becomes part of the process argument vector and may also be stored in shell history. 3. A local user, monitoring agent, diagnostic collector, or process with suitable visibility reads the argument or history entry. 4. The observer reuses the captured password to authenticate. ### Impact Assessment The observer obtains the user's plaintext session passphrase and can assume the privileges available after successful Skill authentication. Exposure may extend further if the user reused the same password elsewhere, although password reuse is not established by the code. ]]>
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/test-billing.js:40
Finding

Billing Test Uses Production Credentials and Performs a Real Charge Request

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
Findings (29)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · scripts/auth-core.js (reported line 83)May include surrounding context.

js
return { locked: true, remainingMinutes: remainingMin };
  }
  
  // Lock expired, reset
  state.lockedUntil = null;
  state.failedAttempts = 0;
  saveJson(AUTH_STATE_FILE, state);

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The CLI accepts the passphrase as a positional argument, which can expose the secret through shell history, process listings, audit tooling, and logs on multi-user systems. This creates a real credential disclosure risk even if the underlying verification logic is otherwise correct.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger conditions are broad and based on common authentication-related words and session start, which can cause the skill to activate in contexts where the user is only discussing passwords rather than requesting access control. Because this skill appears to gate session access and includes commands like uninstalling the auth skill, ambiguous activation increases the risk of unintended interception, denial of service, or socially engineered invocation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The specification states that authentication events and credential-related state are stored in local files, but it does not warn users about this data handling or describe retention, access controls, and sensitivity of the logs. In a local skill environment, undisclosed logging and storage of authentication metadata can create privacy and security risks, especially if audit logs, recovery data, or state files are accessible to other processes or users.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documented trigger conditions are broad enough to activate the authentication skill on generic words like "password" or "auth," which can cause unintended invocation during normal conversation. In an agent context, unexpected activation can interrupt workflows, expose authentication state transitions, or trigger sensitive operations such as logout, recovery, or uninstall paths without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This file is entirely hard-coded in zh-CN and presents all setup, authentication, recovery, and command text only in Simplified Chinese. Under the policy rule for natural-language violations, forcing a specific language is a concern unless the skill explicitly offers language choice or clearly documents a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The manifest hardcodes a live-looking billing API key and declares payment/billing integration inside a package described as a session password/authentication guard. Embedding secrets in a distributable package exposes the credential to anyone with package access, and the unrelated monetization logic increases the attack surface and raises concern about hidden external calls in a security-sensitive skill.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The top-level documentation states the module implements "email recovery," creating an expectation of an actual recovery mechanism. In the implementation, the only related behavior is exposing stored recovery metadata via getRecoveryEmail/getSecurityQuestion and verifying a security answer; there is no email dispatch, token generation, or reset workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code returns authentication prompts and lockout messages only in Chinese string literals. For a general-purpose authentication module, forcing a specific language without user opt-in or documented regional scope is a natural-language policy violation under the locale-choice requirement.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file header advertises a pricing model of 29 USDT buyout and 0.9 USDT per call, while the executable code sets PRICE_PER_CALL to 0.01 USDT and does not implement the documented buyout in the main flow. Security-relevant billing mismatches are dangerous because users and integrators may make consent and trust decisions based on false pricing, enabling deceptive charging behavior or unauthorized access assumptions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code includes a checkPurchased function and comments promising buyout handling, but handleBilling ignores purchase status and always attempts a per-call charge. This can cause previously entitled users to be charged again, which is a real billing integrity issue and could amount to unauthorized repeat charging.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This function performs a live billing charge over the network as soon as it is invoked, with no indication in this file of any prior user confirmation, pre-charge notice, or review step. In a skill context, silent charging is more dangerous because invocation may be indirect or automated, increasing the risk of non-consensual charges and dispute exposure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill sends and displays user-facing content primarily in Chinese, including the email subject and CLI/status messages, without offering a language choice or documenting a locale-specific constraint. This can violate organizational language/locale policy when the skill is not clearly limited to Chinese-speaking users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

In stub mode, the recovery code is written in plaintext to a predictable local file inside the workspace, and the function even returns the code in the result object. In an agent/workspace context, other local processes, skills, or users with workspace access could read the file and use the code to assist account takeover, especially since this module handles password recovery secrets.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The CLI help and command name present this path as a simple verification action, but verifyRecoveryCode has a side effect: on success it sets record.used = true and writes the record back to disk. This is an intent-level contradiction because a user or caller invoking 'verify' would reasonably expect a read/check operation, not one that irreversibly consumes the code.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The header comment describes this as a 'Session Password' module that generates documents for a password-authentication skill, and the document body repeatedly presents implemented security features such as bcrypt hashing, lockouts, recovery email, and audit logs. However, the actual code performs no authentication, hashing, recovery, or security enforcement; it only constructs and writes DOCX files to disk.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/generate-docx.js (reported line 15)May include surrounding context.

js
const OUTPUT_DIR = path.join(process.env.OPENCLAW_WORKSPACE || path.join(process.env.HOME, '.openclaw', 'workspace'), 'session password');

// Create output directory
if (!fs.existsSync(OUTPUT_DIR)) {
  fs.mkdirSync(OUTPUT_DIR, { recursive: true });
}

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code emits password validation feedback exclusively in Chinese from validatePassword(), even though the skill later offers a language choice. A user selecting English would still receive Chinese-only error strings, which is a natural-language locale policy issue because the skill does not consistently honor the user's language preference.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The setup wizard tells users that recovery codes will be sent to the configured email, but this script only validates and stores the email address locally and does not implement any delivery mechanism. This creates a misleading security/recovery guarantee that can cause account lockout and unsafe operational assumptions during incident recovery.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The final success message repeats that forgotten-password recovery codes can be sent by email, but no such functionality exists in the script. Reaffirming a nonexistent recovery path increases the chance that users rely on it and fail to provision alternate recovery controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This test script performs an actual POST to a live billing endpoint using a hardcoded production-looking API key and submits a charge request, so running it can trigger real financial operations rather than a harmless mock test. In the context of a billing integration skill, labeling the action as a test does not reduce the risk because developers or operators may execute it assuming it is non-destructive, causing unauthorized charges or abuse of exposed credentials.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The uninstall flow always requires the literal English string "yes" to proceed, even when the UI is presented in Chinese. This is a real usability and safety flaw because users in the non-English flow may misunderstand the confirmation requirement, causing failed or repeated uninstall attempts, but it does not create unauthorized access or code execution by itself.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
84% confidence
Finding

Using a caret range for bcrypt means installs may resolve to different releases over time, which weakens reproducibility and makes it harder to verify whether a vulnerable version is being pulled in. In a security-focused package, dependency drift is especially undesirable because cryptographic and auth components should be tightly controlled.

Content

Scanner excerpt · package.json (reported line 26)May include surrounding context.

json
"node": ">=18.0.0"
  },
  "dependencies": {
    "bcrypt": "^5.1.1",
    "axios": "^1.6.0"
  },
  "pricing": {

Unverifiable Dependency: bcrypt has 1 known advisory(ies) (CVE-2020-7689 (Integer Overflow or Wraparound and Use of a Broken or Risky Cryptographic Algori)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
90% confidence
Finding

Using an unpinned axios version allows future installs to pick up different releases, complicating verification against known advisories and potentially introducing exploitable HTTP-client issues. Because this skill already advertises external billing/payment communication, axios is likely used for outbound network requests, which makes dependency risk more relevant than in a purely local package.

Content

Scanner excerpt · package.json (reported line 27)May include surrounding context.

json
},
  "dependencies": {
    "bcrypt": "^5.1.1",
    "axios": "^1.6.0"
  },
  "pricing": {
    "type": "paid",

Static analysis

No suspicious patterns detected.